CVE-2026-93964

Source
https://cve.org/CVERecord?id=CVE-2026-93964
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93964.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93964
Published
2026-09-20T05:30:17Z
Modified
2026-09-24T03:30:32Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
NginxProxyManager nginx-proxy-manager Validate Route certificate.js internalCertificate.validate missing authentication
Details

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. Endpoint only processes and echoes back the certificate the caller submits (no stored data leaked); the real risk is unauthenticated openssl processing of attacker input. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-287",
        "CWE-306"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93964.json"
}
References

Affected packages

Git / github.com/nginxproxymanager/nginx-proxy-manager

Affected ranges

Type
GIT
Repo
https://github.com/nginxproxymanager/nginx-proxy-manager
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.0"
        },
        {
            "last_affected":  "2.0"
        },
        {
            "introduced":  "2.1"
        },
        {
            "last_affected":  "2.1"
        },
        {
            "introduced":  "2.1.0"
        },
        {
            "last_affected":  "2.1.0"
        },
        {
            "introduced":  "2.1.1"
        },
        {
            "last_affected":  "2.1.1"
        },
        {
            "introduced":  "2.1.2"
        },
        {
            "last_affected":  "2.1.2"
        },
        {
            "introduced":  "2.2"
        },
        {
            "last_affected":  "2.2"
        },
        {
            "introduced":  "2.2.0"
        },
        {
            "last_affected":  "2.2.0"
        },
        {
            "introduced":  "2.2.1"
        },
        {
            "last_affected":  "2.2.1"
        },
        {
            "introduced":  "2.2.2"
        },
        {
            "last_affected":  "2.2.2"
        },
        {
            "introduced":  "2.2.3"
        },
        {
            "last_affected":  "2.2.3"
        },
        {
            "introduced":  "2.2.4"
        },
        {
            "last_affected":  "2.2.4"
        },
        {
            "introduced":  "2.3"
        },
        {
            "last_affected":  "2.3"
        },
        {
            "introduced":  "2.3.0"
        },
        {
            "last_affected":  "2.3.0"
        },
        {
            "introduced":  "2.3.1"
        },
        {
            "last_affected":  "2.3.1"
        },
        {
            "introduced":  "2.4"
        },
        {
            "last_affected":  "2.4"
        },
        {
            "introduced":  "2.4.0"
        },
        {
            "last_affected":  "2.4.0"
        },
        {
            "introduced":  "2.5"
        },
        {
            "last_affected":  "2.5"
        },
        {
            "introduced":  "2.5.0"
        },
        {
            "last_affected":  "2.5.0"
        },
        {
            "introduced":  "2.6"
        },
        {
            "last_affected":  "2.6"
        },
        {
            "introduced":  "2.6.0"
        },
        {
            "last_affected":  "2.6.0"
        },
        {
            "introduced":  "2.6.1"
        },
        {
            "last_affected":  "2.6.1"
        },
        {
            "introduced":  "2.6.2"
        },
        {
            "last_affected":  "2.6.2"
        },
        {
            "introduced":  "2.7"
        },
        {
            "last_affected":  "2.7"
        },
        {
            "introduced":  "2.7.0"
        },
        {
            "last_affected":  "2.7.0"
        },
        {
            "introduced":  "2.7.1"
        },
        {
            "last_affected":  "2.7.1"
        },
        {
            "introduced":  "2.7.2"
        },
        {
            "last_affected":  "2.7.2"
        },
        {
            "introduced":  "2.7.3"
        },
        {
            "last_affected":  "2.7.3"
        },
        {
            "introduced":  "2.8"
        },
        {
            "last_affected":  "2.8"
        },
        {
            "introduced":  "2.8.0"
        },
        {
            "last_affected":  "2.8.0"
        },
        {
            "introduced":  "2.8.1"
        },
        {
            "last_affected":  "2.8.1"
        },
        {
            "introduced":  "2.9"
        },
        {
            "last_affected":  "2.9"
        },
        {
            "introduced":  "2.9.0"
        },
        {
            "last_affected":  "2.9.0"
        },
        {
            "introduced":  "2.9.1"
        },
        {
            "last_affected":  "2.9.1"
        },
        {
            "introduced":  "2.9.2"
        },
        {
            "last_affected":  "2.9.2"
        },
        {
            "introduced":  "2.9.3"
        },
        {
            "last_affected":  "2.9.3"
        },
        {
            "introduced":  "2.9.4"
        },
        {
            "last_affected":  "2.9.4"
        },
        {
            "introduced":  "2.9.5"
        },
        {
            "last_affected":  "2.9.5"
        },
        {
            "introduced":  "2.9.6"
        },
        {
            "last_affected":  "2.9.6"
        },
        {
            "introduced":  "2.9.7"
        },
        {
            "last_affected":  "2.9.7"
        },
        {
            "introduced":  "2.9.8"
        },
        {
            "last_affected":  "2.9.8"
        },
        {
            "introduced":  "2.9.9"
        },
        {
            "last_affected":  "2.9.9"
        },
        {
            "introduced":  "2.9.10"
        },
        {
            "last_affected":  "2.9.10"
        },
        {
            "introduced":  "2.9.11"
        },
        {
            "last_affected":  "2.9.11"
        },
        {
            "introduced":  "2.9.12"
        },
        {
            "last_affected":  "2.9.12"
        },
        {
            "introduced":  "2.9.13"
        },
        {
            "last_affected":  "2.9.13"
        },
        {
            "introduced":  "2.9.14"
        },
        {
            "last_affected":  "2.9.14"
        },
        {
            "introduced":  "2.9.15"
        },
        {
            "last_affected":  "2.9.15"
        },
        {
            "introduced":  "2.9.16"
        },
        {
            "last_affected":  "2.9.16"
        },
        {
            "introduced":  "2.9.17"
        },
        {
            "last_affected":  "2.9.17"
        },
        {
            "introduced":  "2.9.18"
        },
        {
            "last_affected":  "2.9.18"
        },
        {
            "introduced":  "2.9.19"
        },
        {
            "last_affected":  "2.9.19"
        },
        {
            "introduced":  "2.9.20"
        },
        {
            "last_affected":  "2.9.20"
        },
        {
            "introduced":  "2.9.21"
        },
        {
            "last_affected":  "2.9.21"
        },
        {
            "introduced":  "2.9.22"
        },
        {
            "last_affected":  "2.9.22"
        },
        {
            "introduced":  "2.10"
        },
        {
            "last_affected":  "2.10"
        },
        {
            "introduced":  "2.10.0"
        },
        {
            "last_affected":  "2.10.0"
        },
        {
            "introduced":  "2.10.1"
        },
        {
            "last_affected":  "2.10.1"
        },
        {
            "introduced":  "2.10.2"
        },
        {
            "last_affected":  "2.10.2"
        },
        {
            "introduced":  "2.10.3"
        },
        {
            "last_affected":  "2.10.3"
        },
        {
            "introduced":  "2.10.4"
        },
        {
            "last_affected":  "2.10.4"
        },
        {
            "introduced":  "2.11"
        },
        {
            "last_affected":  "2.11"
        },
        {
            "introduced":  "2.12"
        },
        {
            "last_affected":  "2.12"
        },
        {
            "introduced":  "2.13"
        },
        {
            "last_affected":  "2.13"
        },
        {
            "introduced":  "2.14.0"
        },
        {
            "last_affected":  "2.14.0"
        },
        {
            "introduced":  "2.15.0"
        },
        {
            "last_affected":  "2.15.0"
        },
        {
            "introduced":  "2.15.1"
        },
        {
            "last_affected":  "2.15.1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

2.*
2.0
2.1
2.1.1
2.1.2
2.10
2.10.1
2.10.2
2.10.3
2.10.4
2.11
2.12
2.13
2.14.0
2.15.0
2.15.1
2.2
2.2.1
2.2.2
2.2.3
2.2.4
2.3
2.3.1
2.4
2.5
2.6
2.6.1
2.6.2
2.7
2.7.1
2.7.2
2.7.3
2.8
2.8.1
2.9
2.9.1
2.9.10
2.9.11
2.9.12
2.9.13
2.9.14
2.9.15
2.9.16
2.9.17
2.9.18
2.9.19
2.9.2
2.9.20
2.9.21
2.9.22
2.9.3
2.9.4
2.9.5
2.9.6
2.9.7
2.9.8
2.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93964.json"